Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-5868

14
FAUCET Score

CVE-2023-5868 is a memory disclosure vulnerability in PostgreSQL, also affecting Red Hat products, where specific aggregate function calls with 'unknown'-type arguments can expose sensitive system memory. This medium-severity vulnerability (CVSS 4.3) has a low attack complexity and requires low privileges, potentially leading to the disclosure of confidential information. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.0, < 11.22CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 12.0, < 12.17CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 13.0, < 13.13CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 14.0, < 14.10CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 15.0, < 15.5CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.77%
Probability of exploitation in next 30 days
EPSS Percentile
84.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0278 is in the 95th percentile among its peer group of 21,977 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (52)

beckhoffpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
dhis2patch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
fortinetpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
microsoftpatch availablevia msrc
Product: 18239-16823Fixed in: 14.10-1
microsoftpatch availablevia msrc
Product: cbl2 postgresql 14.10-1 on CBL Mariner 2.0Fixed in: 14.10-1
miniopatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
navidromepatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
netscoutpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
new_relicpatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
nvidiapatch availablevia llm_extracted
Fixed in: 16.1, 15.5, 14.10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: postgresql:12-8020020231128165246.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: postgresql:12-8020020231128165246.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: postgresql:12-8040020231127153301.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: postgresql:13-8040020231127154806.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: postgresql:12-8040020231127153301.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: postgresql:13-8040020231127154806.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: postgresql:12-8040020231127153301.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: postgresql:13-8040020231127154806.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: postgresql:13-8060020231114115246.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: postgresql:12-8060020231128165328.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:13-8080020231114105206.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:12-8080020231128165335.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql:15-8080020231113134015.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql-0:13.13-1.el9_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql:15-9030020231120082734.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: postgresql-0:13.13-1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: postgresql-0:13.13-1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: postgresql:15-9020020231115020618.rhel9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql12-postgresql-0:12.17-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql13-postgresql-0:13.13-1.el7
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-main-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-slim-rhel8:3.74.8-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-main-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-operator-bundle:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-4.1-RHEL-8Fixed in: advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.1.6-6
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.74-RHEL-8Fixed in: advanced-cluster-security/rhacs-operator-bundle:3.74.8-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-central-db-rhel8:4.2.4-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-main-rhel8:4.2.4-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-operator-bundle:4.2.4-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-scanner-db-rhel8:4.2.4-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Security 4.2Fixed in: advanced-cluster-security/rhacs-scanner-db-slim-rhel8:4.2.4-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:13-8090020231114113712.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:12-8090020231128173330.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:15-8090020231114113548.a75119d5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: postgresql:12-8020020231128165246.4cda2c84
View patch
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-postgresql10-postgresql
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql:10/postgresql
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: postgresql

Vendor Advisories (10)

microsoft2023-Dec/CVE-2023-5868Moderate

Postgresql: memory disclosure in aggregate function calls

Dec 12, 2023
redhatCVE-2023-5868Moderate

postgresql: Memory disclosure in aggregate function calls

Nov 9, 2023
fortinetllm-fortinet-520e56ba20767d95MEDIUM

Memory disclosure in aggregate function calls

Jan 1, 2023
new_relicllm-new_relic-174f70192e2a63e9MEDIUM

Memory disclosure in aggregate function calls

dhis2llm-dhis2-6d9cf28ec4a448faMEDIUM

Memory disclosure in aggregate function calls

miniollm-minio-fd4eb95b2864eec1LOW

Memory disclosure in aggregate function calls

navidromellm-navidrome-ce2b472761478a75MEDIUM

Memory disclosure in aggregate function calls

nvidiallm-nvidia-ee81fc93bb6c8816MEDIUM

Memory disclosure in aggregate function calls

beckhoffllm-beckhoff-cf4c32c7ce238aa1MEDIUM

Memory disclosure in aggregate function calls

netscoutllm-netscout-05d5c00e1b23d7d9MEDIUM

Memory disclosure in aggregate function calls

References

lists.debian.org / debian-lts-announce/2023/11/msg00007.html
security.netapp.com / advisory/ntap-20240119-0003
access.redhat.com / errata/RHSA-2023:7545
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7579
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7580
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7581
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7616
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7656
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7666
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7667
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7694
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7695
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7714
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7770
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7772
Third Party Advisory
access.redhat.com / errata/RHSA-2023:7784
access.redhat.com / errata/RHSA-2023:7785
access.redhat.com / errata/RHSA-2023:7883
access.redhat.com / errata/RHSA-2023:7884
access.redhat.com / errata/RHSA-2023:7885
access.redhat.com / errata/RHSA-2024:0304
access.redhat.com / errata/RHSA-2024:0332
access.redhat.com / errata/RHSA-2024:0337
access.redhat.com / security/cve/CVE-2023-5868
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
postgresql.org / about/news/postgresql-161-155-1410-1313-1217-and-1122-released-2749
Release Notes
postgresql.org / support/security/CVE-2023-5868
MitigationVendor Advisory